A critical, easily exploitable vulnerability in Oracle WebCenter Portal lets a low-privileged network attacker fully compromise portal data and impact adjacent products through a scope change.
What Is It
CVE-2026-60564 is a critical vulnerability in the Runtime Tools component of Oracle WebCenter Portal, part of Oracle Fusion Middleware. Oracle describes it as easily exploitable, allowing a low-privileged attacker with network access over HTTP to compromise the product with no user interaction. It carries a CVSS 3.1 base score of 9.6 (CRITICAL), with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N. The scope is marked as changed, meaning a successful attack may significantly impact additional products beyond WebCenter Portal itself.
Why It Matters
Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, up to and including all WebCenter Portal-accessible data, as well as unauthorized read access to critical or all accessible data. In short, the flaw threatens both the integrity and confidentiality of portal data (availability is not impacted). The combination of low attack complexity, only low privileges required, no user interaction, and network reachability over HTTP makes this an attractive target. The scope change amplifies the risk, as the blast radius may extend to other connected products.
What's Vulnerable
The affected product is Oracle WebCenter Portal (vendor: Oracle Corporation). Per Oracle, the affected supported versions are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
The vulnerability was disclosed by Oracle (source identifier [email protected]) and is addressed in the Oracle Critical Patch Update Advisory for July 2026. Organizations running the affected WebCenter Portal versions should consult that advisory and apply the corresponding fixes. As of this record, the NVD entry is in "Received" status. No CISA KEV entry was supplied, so active exploitation is not confirmed here.
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60564, https://nvd.nist.gov/vuln/detail/CVE-2026-60564